mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-04 06:56:56 +02:00
feat: vulnerability-research mode — hand it a repo, it hunts a novel CVE
New --research mode for whitebox/greybox (REPL /research, web 🔬 checkbox, or auto-detected from natural-language focus/objective in PT/EN). Steers the source review to find a NOVEL, CVE-reportable issue instead of a known one: - WHITEBOX_RESEARCH_DOCTRINE: pin version/commit; research known CVEs/advisories (SECURITY.md, CHANGELOG, GHSA, NVD, git history) to de-duplicate; patch-diff / n-day->0-day variant analysis (incomplete fixes, bypasses of a new check, sibling sinks, reintroductions); strict novelty gate (each finding states novel-why + checked-against); benign PoC + dynamic confirm on greybox. - RunConfig.research + is_research_intent(); injected in run_whitebox and the greybox code-review half. - 6 research skills (code/): known_cve_dedup, patch_diff_variant, attack_surface_map, source_to_sink_taint, logic_authz_flaw, dependency_nday_reachability. - Methodology modeled on a real AppSec-research workflow (no specifics copied). 479 agents, 421 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
ed4105999e
commit
9076d30c59
14 files changed
+412
-11
No files matched your search
@@ -533,6 +533,7 @@ async function startExploitation() {
|
||||
chainDepth: Number($('#fieldChain').value),
|
||||
recon: Number($('#fieldRecon').value),
|
||||
quick: $('#fieldQuick') ? $('#fieldQuick').checked : false,
|
||||
research: $('#fieldResearch') ? $('#fieldResearch').checked : false,
|
||||
subscription: state.authMode === 'subscription',
|
||||
mcp: $('#fieldMcp').checked,
|
||||
agents: [...state.selected],
|
||||
|
||||
@@ -221,6 +221,9 @@
|
||||
<div class="section-desc">Optional. Left on <em>unlimited</em>, the run behaves exactly as it always has — full depth, no cap.</div>
|
||||
</div>
|
||||
<div class="field-row">
|
||||
<div class="check-row"><input type="checkbox" id="fieldResearch" /> <label for="fieldResearch"><b>🔬 Research mode</b> — hunt a novel, CVE-reportable bug (whitebox/greybox)</label>
|
||||
<div class="field-help">Known-CVE de-dup + patch-diff variant analysis. Best with a source repo; reports only genuinely new issues (or a concrete patch bypass).</div>
|
||||
</div>
|
||||
<div class="check-row check-quick"><input type="checkbox" id="fieldQuick" /> <label for="fieldQuick"><b>⚡ Quick mode</b> — short, low-cost test</label>
|
||||
<div class="field-help">Economy preset: 1 voter, 1 chain round, light recon, ≤6 agents, eco budget. The big token saver. Wins over the settings below.</div>
|
||||
</div>
|
||||
|
||||
@@ -882,6 +882,7 @@ function sanitizeLaunch(body) {
|
||||
sandbox: !!body.sandbox,
|
||||
typesafe: body.typesafe,
|
||||
quick: !!body.quick,
|
||||
research: !!body.research,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -902,6 +903,7 @@ function buildReplScript(body) {
|
||||
if (body.objective) lines.push(`/objective ${body.objective}`);
|
||||
if (body.outOfScope) lines.push(`/scope-out ${body.outOfScope}`);
|
||||
if (body.creds) lines.push(`/creds ${body.creds}`);
|
||||
if (body.research) lines.push(`/research on`);
|
||||
lines.push((body.agents || []).length ? `/only ${body.agents.join(',')}` : '/only clear');
|
||||
// Economy preset last, so it wins over the per-knob settings above.
|
||||
if (body.quick) lines.push('/quick');
|
||||
|
||||
Reference in new issue
Block a user